CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5667  CVE-2002-1283  Candidate  Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.  Modified (20081001)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall | REVIEWING(1) Christey  Christey> Consider overlap with CVE-2002-1002 ? | See XF:novell-imanager-username-bo(9444) for more info  View
7431  CVE-2003-0604  Candidate  Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF file whose Content-location contains a File:// URL.  Assigned (20030725)  NOOP(1) Christey  Christey> consider MSKB:828026, which *might* address this problem.  View
4481  CVE-2002-0087  Candidate  bindsock in Lotus Domino 5.07 on Solaris allows local users to create arbitrary files via a symlink attack on temporary files.  Modified (20050528)  ACCEPT(4) Balinsky, Cole, Foat, Green | NOOP(3) Christey, Wall, Ziese  Christey> Consider adding BID:4318 | CHANGE> [Foat changed vote from NOOP to ACCEPT] | Christey> CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=463&rt=0&org=sims&doc=93B3ED336951525385256B7D006A3CE3 | VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4125 - Lotus Domino bindsock arbitrary file creation vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0045.html  View
4480  CVE-2002-0086  Candidate  Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable.  Modified (20050528)  ACCEPT(3) Cole, Foat, Green | MODIFY(1) Balinsky | NOOP(3) Christey, Wall, Ziese  Christey> Consider adding BID:4317 | Christey> Consider adding BID:4319 | CHANGE> [Balinsky changed vote from ACCEPT to MODIFY] | Balinsky> Should say 5.0.4 through 5.0.9 (not including version 5.0.9a, which includes the fix) | Balinsky> Additional Modification: Should say "Linux and Solaris" | CHANGE> [Foat changed vote from NOOP to ACCEPT] | Christey> CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=463&rt=0&org=sims&doc=92579CFD6F92B39A85256B7D006AC89B | CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=463&rt=0&org=sims&doc=D52DF997ABFFFC8385256B7D0062AD5C | VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4126 - Lotus Domino bindsock Notes_ExecDirectory buffer overflow vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0046.html | VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4124 - Lotus Domino bindsock PATH buffer overflow vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0044.html  View
4452  CVE-2002-0058  Candidate  Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client"s sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, and possibly other implementations that use vulnerable versions of SDK or JDK.  Proposed (20020315)  ACCEPT(5) Cole, Foat, Green, Wall, Ziese | NOOP(1) Christey  Christey> Consider adding BID:4228 | Christey> XF:java-vm-session-hijacking(8351) | URL:http://www.iss.net/security_center/static/8351.php | HP:HPSBUX0203-186 | URL:http://online.securityfocus.com/advisories/3930 | BID:4228 | URL:http://www.securityfocus.com/bid/4228 | | Need to add "HttpURLConnection" to description (commonly used word) | Christey> ADDREF COMPAQ:SSRT0822 | Christey> COMPAQ:SSRT0822 | Christey> SGI:20020807-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20020807-01-I | Christey> BID:4228 | URL:http://www.securityfocus.com/bid/4228  View

Page 316 of 20943, showing 5 records out of 104715 total, starting on record 1576, ending on 1580

Actions